← Home

color-convert

Plain color conversion functions

39
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

qix

Keywords

colorcolourconvertconverterconversionrgbhslhsvhwbcmykansiansi16

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:eval-usage AI (semgrep): eval() in color-convert is part of a legacy JSON parser polyfill (classic '(' + text + ')' pattern), not arbitrary code execution. This is a stable false positive for this package. ai
provenance publisher-changed AI (provenance): Legitimate maintainer transition from harth to qix, a well-established npm publisher who co-maintains the color-convert ecosystem. ai
maintainer-change maintainer-added AI (maintainer-change): moox and qix are known co-maintainers of color-convert; moox matches the GitHub repo owner MoOx/color-convert. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require in a browserify-generated bundle is standard boilerplate, not arbitrary module loading. Stable false positive for this package. ai
dependencies unvetted-dep:color-name AI (dependencies): color-name is a well-known, widely-used color names library and a natural, stable dependency for color-convert across all versions. ai
provenance no-provenance AI (provenance): Package is 5429 days old and predates Sigstore provenance; absence is expected and not a risk signal for this package. ai

Versions (showing 39 of 39)

Version Deps Published
3.1.3 1 / 4
3.1.2 1 / 4
3.1.0 1 / 4
3.0.1 1 / 4
3.0.0 1 / 4
2.0.1 1 / 2
2.0.0 1 / 2
1.9.3 1 / 2
1.9.2 1 / 2
1.9.1 1 / 2
1.9.0 1 / 2
1.8.2 1 / 2
1.8.1 1 / 2
1.8.0 1 / 2
1.7.0 1 / 2
1.6.0 1 / 2
1.5.0 0 / 2
1.4.0 0 / 2
1.3.1 0 / 2
1.3.0 0 / 2
1.2.2 0 / 2
1.2.1 0 / 2
1.2.0 0 / 2
1.1.2 0 / 2
1.1.1 0 / 2
1.1.0 0 / 2
1.0.0 0 / 2
0.7.0 0 / 1
0.6.0 0 / 0
0.5.3 0 / 0
0.5.2 0 / 4
0.5.1 0 / 4
0.5.0 0 / 2
0.4.0 0 / 2
0.3.4 0 / 2
0.3.1 0 / 2
0.2.1 0 / 2
0.2.0 0 / 2
0.1.0 0 / 2